Leadde Logo

Preventing Business Email Compromise and Fake Invoice Fraud

Explains the definition and risks of business email compromise, analyzes attacker tactics, and outlines strict verification channels and approval workflows to safeguard company finances.
LBy Leadde Updated August 21, 2026

How a Fake Invoice Gets Paid

Business email compromise works by inserting one plausible instruction into a real conversation. The attacker gains access to or convincingly imitates a supplier's mailbox, waits for an invoice cycle, and sends updated bank details at the moment a payment is already expected. Nothing about the request looks unusual, because the timing is genuine.

That is why this fraud defeats controls built to catch unusual activity. The supplier is real, the invoice amount matches the purchase order, the email thread has months of history above it, and the only altered element is a sort code. The material to leave in the source document is any real supplier detail: names, account numbers, and reproductions of genuine invoices must be replaced with fabricated examples, because a training video showing a real payment instruction is itself a document worth stealing.

The template walks the fraud through eight scenes: two on how the attacker gets inside the conversation, one on the timing that makes the request look normal, one on the urgency and confidentiality pressure applied to the approver, two on the out-of-band verification that stops it, one on the approval limits that contain it, and one on what to do in the first hour after a suspect payment.

How to Train a Verification Rule Finance Will Not Waive

Payment fraud training is delivered to people who are measured on paying suppliers promptly. Any control presented as an additional delay will be waived by someone senior under time pressure, which is exactly the situation the attacker is engineering.

Make out-of-band verification a single defined action

Make out-of-band verification a single defined action

Call the number already on file, never the one in the email. One sentence, one phone number source, no interpretation. Verification described as "confirm through a trusted channel" gets satisfied by replying to the thread.

Attach the rule to bank changes, not to amounts

Thresholds invite the attacker to sit below them. Any change to payment details, at any value, triggers the same call, which is both simpler to remember and harder to work around.

Name urgency and confidentiality as signals

Requests to bypass process because of a deal, an audit, or an acquisition are the pattern. Framing pressure itself as the indicator protects staff who cannot judge the underlying business claim.

Give approvers explicit permission to delay

Most losses involve someone who was uneasy and approved anyway. Stating that no legitimate supplier will lose a relationship over a verification call is the sentence that changes behaviour.

Upload the authorisation policy finance already applies

Upload the payment authorisation policy, the vendor bank change procedure, or the accounts payable checklist in PDF, DOCX, DOC, PPTX, or TXT, up to 200 MB. Scenes come back ready to edit; the original stays as it is.

Verify the Bank Change, Not the Email

Bring the payment authorisation policy finance already applies across, review the scenes, and publish before the next quarter-end run.

avatar

Start With This Template. Finish With a Video Ready to Share.

Add your onboarding guide or help-center pages and generate an editable draft in minutes.